REvil threatens to release Apple’s hardware schematics
The ransomware gang has tied its extortion scheme to the firm’s latest launch event
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The group behind the REvil ransomware strain have threatened to release confidential Apple hardware schematics unless the tech giant, or its supplier, pays a sizeable ransom fee.
The notorious group claims to have breached the Taiwanese firm Quanta Computer, one of the biggest hardware manufacturers in the world, making away with the blueprints of various Apple products.
In a message posted on the dark web, the group said Quanta refused to pay the ransom to reclaim their stolen data and as a result, the hackers had decided to extort Apple instead, according to the Record.
The REvil group posted 21 screenshots depicting MacBook schematics as proof for the infiltration and threatened to release new blueprints every day until either Apple or Quanta pay the demand.
“In order not to wait for the upcoming Apple presentations, today, we, the REvil group, will provide data on the upcoming releases of the company so beloved by many,” the hackers’ note said.
RELATED RESOURCE
The business guide to ransomware
Everything you need to know to keep your company afloat
“Tim Cook can say thank you Quanta. From our side, a lot of time has been devoted to solving this problem. Quanta has made it clear to use that it does not care about the data of its customers and employees, thereby allowing the publication and sale of all data we have.”
They also claimed to be negotiating with “several major brands” to sell this data, presumably many of Quanta Computer’s clients, while setting a 1 May deadline for Apple to “buy back” the confidential and personal data. Quanta Computer serves a handful of major companies including Microsoft and HP.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The announcement was made to coincide with the major Apple launch event in which the firm released a slew of new products. The ‘Spring Loaded’ event saw the company launch an M1-powered iMac with a 4.5K Retina display, a new iPad Pro also fitted with the M1 chip as well as purple iPhone 12 variants alongside other minor launches.
The highly active ransomware gang most recently targeted the Harris Federation academy trust of 48 schools based across London in the UK. This led to 37,000 students being locked out of their emails and coursework. Acer also fell victim to a record $50 million ransomware attack last month.
Its activities had previously led to the group generating more than $100 million in one year from extorting large businesses, including the infamous Travelex hack in January 2020. The REvil group has plans to raise its overall income to more than $2 billion over 2021.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Palo Alto Networks CEO hails ‘the end of identity silos’ as firm closes CyberArk acquisitionNews Palo Alto Networks' CEO Nikesh Arora says the $25bn CyberArk acquisition heralds "the end of identity silos" for customers, enabling them to supercharge privileged access management.
-
Google says hacker groups are using Gemini to augment attacksNews Google Threat Intelligence Group has shut down repeated attempts to misuse the Gemini model family
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwiseNews Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals
-
Everything we know so far about the Nike data breachNews Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Hacker offering US engineering firm data online after alleged breachNews Data relating to Tampa Electric Company, Duke Energy Florida, and American Electric Power was allegedly stolen
-
Cybersecurity experts face 20 years in prison following ransomware campaignTwo men used their tech expertise to carry out ALPHV BlackCat ransomware attacks
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement